Module 1 of 5
Building a Client Rollout Plan
Course 1 covered why p=none isn't real protection. This module covers the part that actually matters for an MSP: how to move a client off it without breaking their mail.
The standard staged approach
p=none -> p=quarantine; pct=10 -> ramp pct up -> p=quarantine; pct=100
-> p=reject; pct=10 -> ramp pct up -> p=reject; pct=100
Each stage exists for a reason:
p=none– pure observation. You're not blocking anything yet; you're building a real picture of every sender claiming to be this domain, using the aggregate reports Module 5 of Course 1 covered.- Low-
pctquarantine – start enforcing against a small slice of mail. If something legitimate breaks, the blast radius is 10% of traffic, not all of it, and you'll see it in the next report cycle before ramping further. - Full quarantine, then reject – only once quarantine at 100% has run clean for a real stretch of time (not a day or two) do you move toward outright rejection, using the same low-
pct-then-ramp pattern.
Why skipping straight to p=reject is a real risk
The tempting shortcut – publish p=reject immediately because you're confident the client's real senders are all covered – fails in a specific, predictable way: you find out what you missed by a client calling you, not by a report. A vendor's marketing platform that's been sending on the client's behalf for two years, never audited, silently starts bouncing. There's no visibility step between "reject" and "someone's real mail didn't arrive."
What "ready to escalate" actually looks like
Not a timeline – a signal: aggregate reports showing zero unexplained failures from legitimate sources across a sustained window (several report cycles, not one). If a real sender is still failing, that's the thing to fix before tightening p= further, not something to tighten past.
Run ActiScan's DMARC checker to see exactly where a client's policy sits today – if it's been at p=none for months with nobody watching the reports, that's the actual starting point for this conversation.
Try it yourself: DMARC Record Checker